Help - Search - Members - Calendar
Full Version: Question for whenusing DW and Shadowdefender
Gladiator Security Forum > SoftSphere Technologies Support Forums > DefenseWall HIPS
hawkwind
Is it at all possible when using shadowdefender to be able to save defensewalls untrusted list and file and registry tracks changes, in shadowdefenders exclusion list, whilst in shadow mode?
Ilya Rabinovich
I have no idea. Ask SD developers about an ability to keep certain registry keys non-rollback.
Creer
QUOTE (hawkwind @ Oct 15 2009, 11:11 PM) *
Is it at all possible when using shadowdefender to be able to save defensewalls untrusted list and file and registry tracks changes, in shadowdefenders exclusion list, whilst in shadow mode?

As far as I know SD doesn't offer registry exclusion list, but as Ilya said it will be better to ask the source - Tony SD developer.
hawkwind
Thanks Ilya and Creer :)
Yes Shadowdefender does not offer registry exclusion list so i guess the answer is no then.

Thanks
hawkwind
I have received a reply from Shadowdefenders developer, Tony

QUOTE
SD can't add registry to Exclusion List up to now.
and there is also no plan to add it.
because if it was allowed, there will be a big security hole in Shadow Defender.
SD should use standard Windows APIs to manipulate the registry,
but the Windows APIs maybe are intercepted by some rootkits,


I guess its no big deal as i normally only fire up Shadowdefender when other people use the computer.
Creer
QUOTE (hawkwind @ Oct 16 2009, 03:12 PM) *
I have received a reply from Shadowdefenders developer, Tony

QUOTE
SD can't add registry to Exclusion List up to now.
and there is also no plan to add it.
because if it was allowed, there will be a big security hole in Shadow Defender.
SD should use standard Windows APIs to manipulate the registry,
but the Windows APIs maybe are intercepted by some rootkits,


I guess its no big deal as i normally only fire up Shadowdefender when other people use the computer.

Yup, you are right I do the same. But since you for example enter in shadow mode only one partition (not all), files saved on second non-shadowed partition during SD session, and after restart will be still there. But after restart you won't find them in DW untrusted application list - so they will be Trusted!
There are two solution of this problem.
You can:
1. Always shadow all partitions
or
2. Make an container - special folder on the second partition (if you often save there files from eg. browsers or torrents software) and before enter into shadow mode, add this folder to Untrusted DW list. After that you can be sure that whatever new files will be there - they are always be Untrusted)
hawkwind
Thanks Creer, that is what i have done good.gif
Creer
QUOTE (hawkwind @ Oct 17 2009, 03:17 PM) *
Thanks Creer, that is what i have done good.gif

You are welcome :)
jjmonge
Creer did you tested DW?in youtube?thanks
Creer
QUOTE (jjmonge @ Oct 18 2009, 02:49 AM) *
Creer did you tested DW?in youtube?thanks

Hi jjmonge,

yes I did, but that was v2.51:
http://www.youtube.com/user/MalwareRemovalVideo
This is a "lo-fi" version of our main content. To view the full version with more information, formatting and images, please click here.
Invision Power Board © 2001-2009 Invision Power Services, Inc.